CVE-2014-2538: Joshua Peek Rack-SSL
Medium severity, CVSS 4.3. EPSS: 2.2% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party adapters such as JRuby-Rack.
Affected products
- Joshua Peek Rack-SSL: up to and including 1.3.4; version 1.0.0 only; version 1.1.0 only; version 1.2.0 only; version 1.3.0 only; version 1.3.1 only; …
Published 2014-03-25. Last modified 2026-06-17.